Ò׽ؽØÍ¼Èí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

PHP¼ÓÃÜÀ©Õ¹¿âMcrypt°²×°¼°Ó¦Óü¼ÇÉ

PHP³ÌÐòÔ±ÃÇÔÚ±àд´úÂë³ÌÐòʱ£¬³ýÁËÒª±£Ö¤´úÂëµÄ¸ßÐÔÄÜÖ®Í⣬»¹ÓÐÒ»µãÊǷdz£ÖØÒªµÄ£¬ÄǾÍÊdzÌÐòµÄ°²È«ÐÔ±£ÕÏ¡£PHP³ýÁË×Ô´øµÄ¼¸ÖÖ¼ÓÃܺ¯ÊýÍ⣬»¹Óй¦ÄܸüÈ«ÃæµÄPHP¼ÓÃÜÀ©Õ¹¿âMcryptºÍMhash¡£
ÆäÖУ¬McryptÀ©Õ¹¿â¿ÉÒÔʵÏÖ¼ÓÃܽâÃܹ¦ÄÜ£¬¾ÍÊǼÈÄܽ«Ã÷ÎļÓÃÜ£¬Ò²¿ÉÒÔÃÜÎÄ»¹Ô­¡£
1.PHP¼ÓÃÜÀ©Õ¹¿âMcrypt°²×°
ÔÚ±ê×¼µÄPHP°²×°¹ý³ÌÖв¢Ã»ÓаÑMrcypt°²×°ÉÏ£¬µ«PHPµÄÖ÷Ŀ¼Ï°üº¬ÁËlibmcrypt.dllºÍlibmhash.dllÎļþ (libmhash.dllÊÇMhashÀ©Õ¹¿â£¬ÕâÀï¿ÉÒÔÒ»Æð×°ÉÏ)¡£Ê×ÏÈ£¬½«ÕâÁ½¸öÎļþ¸´ÖƵ½ÏµÍ³Ä¿Â¼windows\system32Ï£¬È»ºóÔÚ PHP.iniÎļþÖа´Ctrl+F¿ì½Ý¼üÌø³ö²éÕÒ¿ò£¬²¢ÕÒµ½£»extension=php-mcrypt.dllºÍ; extension=php_mhash.dllÕâÁ½¸öÓï¾ä£¬½Ó׎«Ç°ÃæµÄ“£»”È¥µô£»×îºó£¬±£´æ²¢ÖØÆôApache·þÎñÆ÷¼´¿ÉÉúЧ¡£
2.PHP¼ÓÃÜÀ©Õ¹¿âMcryptµÄËã·¨ºÍ¼ÓÃÜģʽ
Mcrypt¿âÖ§³Ö20¶àÖÖ¼ÓÃÜËã·¨ºÍ8ÖÖ¼ÓÃÜģʽ£¬¾ßÌå¿ÉÒÔͨ¹ýº¯Êýmcrypt_list_algorithms()ºÍmcrypt_list_modes()À´ÏÔʾ£¬½á¹ûÈçÏ£º
McryptÖ§³ÖµÄËã·¨ÓУºcast-128 gost rijndael-128 twofish arcfour cast-256 loki97 rijndael-192 saferplus wake blowfish-compat des rijndael-256 serpent xtea blowfish enigma rc2 tripledes
McryptÖ§³ÖµÄ¼ÓÃÜģʽÓУºcbc cfb ctr ecb ncfb nofb ofb stream
ÕâЩËã·¨ºÍģʽÔÚÓ¦ÓÃÖÐÒªÒÔ³£Á¿À´±íʾ£¬Ð´µÄʱºò¼ÓÉÏǰ׺MCRYPT_ºÍMCRYPT_À´±íʾ£¬ÈçÏÂÃæMcryptÓ¦ÓõÄÀý×Ó£º
DESËã·¨±íʾΪMCRYPT_DES;
ECBģʽ±íʾΪMCRYPT_MODE_ECB£»
3.PHP¼ÓÃÜÀ©Õ¹¿âMcryptÓ¦ÓÃ
ÏÈ¿´Ò»¸öÀý×Ó£¬Á˽âMcryptµÄ¹¤×÷Á÷³Ì£¬ÔÙÀ´¿´¿´²¿·ÖÁ÷³ÌʹÓõĺ¯Êý£º
< ?php $str = "ÎÒµÄÃû×ÖÊÇ£¿Ò»°ãÈËÎÒ²»¸æËßËû£¡"; //¼ÓÃÜÄÚÈÝ $key = "key:111"; //ÃÜÔ¿ $cipher = MCRYPT_DES; //ÃÜÂëÀàÐÍ $modes = MCRYPT_MODE_ECB; //ÃÜÂëģʽ $iv = mcrypt_create_iv(mcrypt_get_iv_size($cipher,$modes),MCRYPT_RAND);//³õʼ»¯ÏòÁ¿ echo "¼ÓÃÜÃ÷ÎÄ£º".$str."<p>"; $str_encrypt = mcrypt_encrypt($cipher,$key,$str,$modes,$iv); //¼ÓÃܺ¯Êý echo "¼ÓÃÜÃÜÎÄ£º".$str_encrypt." <p>"; $str_decrypt = mcrypt_decrypt($cipher,$key,$str_encrypt,$modes,$iv); //½âÃܺ¯Êý echo "»¹Ô­£º".$str_decrypt; ?>
ÔËÐнá¹û£º
¼ÓÃÜÃ÷ÎÄ£ºÎÒµÄÃû×ÖÊÇ£¿Ò»°ãÈËÎÒ²»¸æËßËû£¡
¼ÓÃÜÃÜÎÄ£º ï³盌?]鸴?q攦軄L Ц 郺葄"簻 Ɩ


Ïà¹ØÎĵµ£º

¡¾×ª¡¿¸ß¼¶PHPÓ¦ÓóÌÐò©¶´ÉóºË¼¼Êõ




×÷ÕߣºPh4nt0m Security Team
À´Ô´£ºhttp://www.ph4nt0m.org-a.googlepages.com/PSTZine_0x03_0x06.txt
==Ph4nt0m Security Team==

Issue 0x03, Phile #0x06 of 0x07

|=---------------------------------------- ......

FCKeditor µÄÅäÖúÍʹÓ÷½·¨(for PHP)

  FCKeditor ÊÇÒ»¸öÊ®·ÖÇ¿´óµÄÍøÒ³Îı¾±à¼­Æ÷£¬ËüÖ§³Ö¶àÖֽű¾±à³ÌÓïÑÔ(°üÀ¨ PHP)ºÍÖ§³Ö¶à¹úÓïÑÔ¡£
    FCKeditor ½ØÖÁ 2008Äê4ÔÂ6ÈÕ£¬Æä×îа汾ÊÇ 2.6RC£¬RC ¾ÍÊÇ Release Candidate£¬ÐÞ¶©ºóµÄºòÑ¡°æ±¾£¬ºÜ¿ÉÄÜ×÷Ϊ¸Ã°æ±¾µÄÎȶ¨°æÔÚδÀ´·¢²¼¡£Ä¿Ç°µÄ×îеÄÎȶ¨°æ(Latest Stable)ÊÇ 2.5.1¡£ÎÒÃÇ¿ÉÒÔµ ......

phpÐòÁл¯

1£®Ç°ÑÔ
PHP £¨´Ó PHP 3.05
¿ªÊ¼£©Îª±£´æ¶ÔÏóÌṩÁËÒ»×éÐòÁл¯ºÍ·´ÐòÁл¯µÄº¯Êý£ºserialize¡¢unserialize¡£²»¹ýÔÚ PHP
ÊÖ²áÖжÔÕâÁ½¸öº¯ÊýµÄ˵Ã÷½öÏÞÓÚÈçºÎʹÓ㬶ø¶ÔÐòÁл¯½á¹ûµÄ¸ñʽȴû×öÈκÎ˵Ã÷¡£Òò´Ë£¬Õâ¶ÔÔÚÆäËûÓïÑÔÖÐʵÏÖ PHP
·½Ê½µÄÐòÁл¯À´Ëµ£¬¾Í±È½ÏÂé·³ÁË¡£ËäÈ»ÒÔǰҲËѼ¯ÁËһЩÆäËûÓïÑÔʵÏÖµÄ PHP ÐòÁл¯µ ......

IISÏÂPHPµÄISAPIºÍFastCGI±È½Ï

    Ô­ÎÄÁ´½Ó£ºhttp://www.williamlong.info/archives/1846.html
    ÔÚWindows IIS
6.0ÏÂÅäÖÃPHP
£¬Í¨³£ÓÐCGI
¡¢ISAPI
ºÍFastCGI
ÈýÖÖÅäÖ÷½Ê½£¬ÕâÈýÖÖģʽ¶¼¿ÉÒÔÔÚIIS
6.0ϳɹ¦ÔËÐУ¬ÏÂÃæÎҾͽ²Ò»ÏÂÕâÈýÖÖ·½Ê½ÅäÖõÄÇø±ðºÍÐÔÄÜÉϵIJîÒì¡£
¡¡¡¡1¡¢CGI
£¨Í¨ÓÃÍø¹Ø½Ó¿Ú/Common Ga ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØÍ¼ | ¸ÓICP±¸09004571ºÅ